CVE-2022-36399 – WordPress Booked Plugin < 2.4.4 is vulnerable to Sensitive Data Exposure
https://notcve.org/view.php?id=CVE-2022-36399
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for WordPress | Calendars.This issue affects Booked - Appointment Booking for WordPress | Calendars: from n/a before 2.4.4. Vulnerabilidad de exposición de información confidencial a un actor no autorizado en BoxyStudio Booked - Appointment Booking for WordPress | Calendars. Este problema afecta a Booked - Appointment Booking for WordPress | Calendars: desde n/a antes de 2.4.4. The Booked plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.4. This can allow unauthenticated attackers to extract sensitive appointment-related data from the database. • https://patchstack.com/database/vulnerability/booked/wordpress-booked-plugin-2-4-unauth-appointment-data-exposure-vulnerability?_s_id=cve • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2022-30706
https://notcve.org/view.php?id=CVE-2022-30706
Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL. Una vulnerabilidad de redireccionamiento abierto en Booked versiones anteriores a 3.3, permite a un atacante remoto no autenticado redirigir a un usuario a un sitio web arbitrario y conducir un ataque de phishing haciendo que el usuario acceda a una URL especialmente diseñada. • https://jvn.jp/en/jp/JVN75063798 https://www.bookedscheduler.com • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •